Partner iGamingAsk a question
Menu

An email list is the one traffic channel an affiliate fully owns — no algorithm change can take a subscriber list away the way one can take away search rankings or a platform's goodwill. It is also the traffic channel with the most explicit legal rules attached to it, because sending marketing email is regulated whether or not the product being marketed is gambling. Get the list-building step wrong and the compliance problem exists before the first send.

In the UK, electronic marketing — email, text, and in-app messages — is governed by the Privacy and Electronic Communications Regulations, and the Information Commissioner's Office sets out the standard plainly: you can only send marketing by electronic mail if you have valid consent, or you meet every condition of the narrow exception for existing customers the regulator calls the "soft opt-in" — see the ICO's guidance on electronic mail marketing. Valid consent under UK GDPR has to be freely given, specific to marketing (not bundled into a general terms checkbox), informed, and given through a clear affirmative action such as ticking an unchecked box. A pre-ticked box does not count. Consent is also "for the time being" — a subscriber can withdraw it at any moment, and every marketing send after that point has to respect the withdrawal.

For a gambling-adjacent list, the UK's non-broadcast advertising code adds a second layer on top of PECR consent: the Advertising Standards Authority's CAP Code Section 16 requires gambling marketing to be socially responsible, and it states outright that the rules apply to "marketing by third parties (for example, affiliate marketers) acting on an advertiser's behalf." An affiliate's list is not exempt because the affiliate itself is not the operator. The code also bars targeting under-18s through the selection of media or context — which is a data-collection question as much as a content question: a signup form that does not verify age, feeding a list that gets gambling-adjacent content, is a compliance gap before a single email goes out.

Building the list without borrowing trouble

  • Double opt-in, always. A second confirmation click is the cleanest evidence that consent was freely given, specific, informed and unambiguous — the standard UK GDPR sets for valid consent. It is also the practical defence if a subscriber later disputes ever signing up.
  • Age gate at the point of collection. A checkbox confirming the subscriber is over 18 (or the higher age threshold that applies in some markets) belongs on the same form as the consent checkbox, not on a separate page the subscriber may skip.
  • Say what the list is for, in the signup copy. "Weekly odds and bonus roundup for UK bettors" is specific; "join our newsletter" is not, and specificity is one of the four conditions PECR consent has to meet.
  • Never buy or scrape a list. A purchased list carries no verifiable consent trail for your specific marketing purpose, and the soft opt-in exception only ever applies to your own existing customers — it cannot be inherited from someone else's list.

What to send, and how often

Three content types carry a list without becoming spam: a weekly roundup of published operator terms changes (new welcome offers, changed wagering requirements — factual, sourced, dated); a monthly deep piece cross-posted from the guide or blog, sent as a summary with a link rather than the full text; and an occasional single-topic email tied to a real event, such as a licence renewal or a regulatory change that affects the subscriber's market. Cadence matters more than volume: a weekly send that a subscriber expects outperforms a daily send that trains the same subscriber to stop opening.

A practical weekly template that holds up over time: one short lead item (a single change worth knowing this week, three or four sentences), one longer link-out to a guide or program review, and one closing line restating what the list is for and how to leave it. Resist the urge to add a fourth section once the first three are working — list fatigue tends to arrive from length creeping up gradually, not from a single bad send.

A worked deliverability check

Say a list of 2,000 subscribers has a 22% open rate and a 1.1% unsubscribe rate on a given send — 440 opens, 22 unsubscribes. An unsubscribe at that rate is not the number to worry about; a subscriber choosing to leave cleanly, through the unsubscribe link, generally reads to a mailbox provider as healthy list hygiene rather than a warning sign. The metric that actually damages a sending domain's reputation is the spam-complaint rate — the share of recipients who mark a message as spam instead of unsubscribing — and Google's own email sender guidelines set the bulk-sender threshold at under 0.3%, with delivery already degrading well before that ceiling. On the same 2,000-subscriber send, 0.3% is six complaints; a handful of complaints, not a stack of unsubscribes, is the number worth tracking send over send.

Not every subscriber consented the same way, and not every subscriber sits in the same market. A subscriber captured through the narrow soft opt-in exception (an existing customer relationship, offered a chance to opt out at collection and in every subsequent message) should never receive content outside the specific product context that exception was built around — mixing that segment into a general newsletter list retroactively breaks the basis the consent rested on. Separately, a UK subscriber and a German subscriber are not governed by the same advertising rules, and a single blanket send risks applying the more permissive market's wording to the stricter one. Two segmentation axes — consent basis, and market — should exist in your list tooling before your first campaign, not retrofitted after a complaint.

Respecting self-exclusion inside a list

A subscriber who self-excludes from gambling — through an operator's own tools or a national scheme — has told the wider industry something specific about their relationship with the product your list is about. An unsubscribe request from a list built around gambling content should be honoured immediately and without a "are you sure" step, and any subscriber who explicitly mentions self-exclusion or a gambling problem in a reply should be removed from the list on sight, independent of whether they formally unsubscribed. This is not just good practice; CAP Code Section 16's requirement that gambling marketing "protect... vulnerable persons from being harmed or exploited" applies to every channel a third-party marketer controls, a list included.

Deliverability basics that also protect compliance

  • Authenticate the sending domain with SPF, DKIM and DMARC before the first campaign — an unauthenticated domain is both a deliverability risk and a sign, to a suspicious mailbox provider, of exactly the kind of unsolicited mail PECR exists to stop.
  • Keep an unsubscribe link one click away, every send — not because a platform requires it cosmetically, but because immediate, frictionless withdrawal of consent is what the regulation actually asks for.
  • Prune inactive subscribers on a schedule (six months with no open is a reasonable line) rather than mailing a stale list indefinitely — engagement, not list size, is what a mailbox provider scores.

FAQ

Can I email people who signed up for a different newsletter on the same site?

Only if the original consent was specific to the content type you now want to send. PECR's "specific" requirement means consent to one kind of marketing does not automatically cover another; the safer route is a fresh opt-in for the new content type, phrased plainly about what it is.

Do I need a separate privacy notice for a mailing list?

You need to tell subscribers, at the point of signup, who is contacting them, for what purpose, and how to withdraw — that information can live in a linked privacy policy rather than the signup form itself, but it has to be reachable from the form, not buried three clicks away.

What counts as a "soft opt-in" and can I use it for a gambling-content list?

The soft opt-in exception applies narrowly to your own existing customers, contacted about similar products to what they already bought from you, with an opt-out offered at collection and in every message. It is a narrow exception, not a general licence to add anyone who has ever interacted with the site — most affiliate mailing lists should plan around explicit opt-in as the default.

What to do this week

  • Check your signup form: is the marketing consent checkbox unticked by default, and separate from any general terms-acceptance box?
  • Add an explicit age confirmation to the same form if it is not already there.
  • Check your last three sends' spam-complaint rate, if your sending platform reports it, rather than watching unsubscribes as the danger signal.
  • Write one line of standing process for what happens the moment a subscriber mentions self-exclusion — it should not require a decision in the moment.
  • If your list has never been segmented by market, split it before your next send — a UK subscriber and a German subscriber are governed by different rules, covered in our compliance guide, and a single blanket email risks the stricter market's rule for everyone.

Email sits alongside the other channels in our traffic sources guide and the platform-specific rules in our video and streaming guide — the three together are the traffic side of the site; the SEO guide covers the fourth. Terms used above — soft opt-in, double opt-in, self-exclusion — are defined in the glossary if any are unfamiliar.

Next in this trackVideo and Streaming for iGaming Affiliates